One day you're just living your life. The next, you get an email saying your information was part of a data breach, and suddenly you're wondering if someone's out there opening a credit card in your name.
Timing matters here. The first 24 to 48 hours after a breach are the most important for protecting your accounts and limiting fraud. You don't need to be a security expert to handle it well. You just need a plan.
Here's what to do, in order.
What is a data breach, exactly?
A data breach happens when someone gains unauthorized access to sensitive information, like:
- Passwords
- Credit card numbers
- Social Security numbers
- Bank account details
- Medical records
- Email addresses
Breaches usually happen through hacked websites, phishing scams, stolen devices, or weak security systems. Once your info is out there, it can be sold online or used directly for fraud, identity theft, or account takeovers.
Even if the company says "there's no evidence of misuse," treat it like your information is at risk and act accordingly.

The first 24 hours: what to do right away
Confirm the notice is real
Scammers send fake "security alert" emails right after real breaches, because they know people are already on edge. Before you click anything:
- Check the sender's email address closely
- Go directly to the company's website instead of clicking email links
- Look for an official breach announcement or support page
A real notice explains what happened, when, and exactly what information was exposed.
Figure out which accounts are exposed
Make a quick list of accounts tied to the breached company or email address. Start with:
- Banking and credit cards
- Shopping sites with saved payment info
- Tax accounts
- Health portals
Your email account matters most, since it's usually the key to resetting passwords everywhere else.
Change your passwords
Start with your most sensitive accounts: email, banking, credit cards, and investments. Use strong, unique passwords for each one. If keeping track of them feels impossible, a password manager makes it easy.
Turn on multi-factor authentication (MFA)
MFA adds a second step before anyone can log in, so even a stolen password isn't enough on its own. Turn it on for email, banking, tax services, and anywhere else it's offered. Authentication apps are stronger than text-message codes.
Sign out of old devices
Review active sessions on your important accounts and log out anywhere you no longer use, like old phones, shared computers, or public devices. Most services let you do this from account settings in a couple of clicks.

Protect your credit before it's a problem
The biggest risk after a breach is someone opening new accounts in your name. Here's how to shut that down fast.
Fraud alert vs. credit freeze
Fraud alert
- Free to place
- Lasts one year
- Tells lenders to verify your identity before approving new credit
Credit freeze
- Free under U.S. law
- Blocks most lenders from accessing your credit report at all
- Can be lifted temporarily when you need it
- The stronger option if your Social Security number was exposed
Contact all three credit bureaus
You'll need to reach out to each one separately: Equifax, Experian, and TransUnion. Most freezes and alerts can be placed online in a few minutes.
Pull your credit reports
Head to AnnualCreditReport.com for your free reports and look for anything unfamiliar: unknown accounts, hard inquiries you didn't authorize, wrong addresses, or collection notices. Dispute anything that doesn't check out.
Keep a simple recovery log
A basic running list makes the whole process easier to manage, and gives you a record if you need to dispute charges later. Track the date, who you contacted, what the issue was, and the current status. For example:
May 27 — Bank fraud department — Unauthorized charge — PendingMay 28 — Experian — Credit freeze placed — Complete
Save confirmation emails, case numbers, and any dispute letters as you go. Set a reminder to check your accounts and credit reports regularly for at least 12 months after the breach.
If identity theft actually happens
If you spot suspicious activity, move fast:
- Contact your bank or card issuer to freeze affected accounts, reverse fraudulent charges, and get new cards issued.
- File a report at IdentityTheft.gov. The FTC's site builds you a personalized recovery plan and generates documentation for disputes.
- Dispute fraudulent accounts with both the creditor and the credit bureaus. Keep copies of everything.
- Check your tax and government accounts. Identity thieves sometimes use stolen info to file fake tax returns or claim benefits. Contact the IRS or relevant agency if anything looks off.
- File a police report if a crime was committed using your identity, or if a creditor, employer, or landlord asks for proof.
Staying protected long after the breach
Some stolen information stays in circulation for years, so a few ongoing habits go a long way:
- Accept free credit monitoring if the company offers it, especially if it covers all three bureaus. Check how long it lasts and whether it auto-renews at a cost.
- Use a password manager so you're never relying on memory (or "Password123!") to keep accounts secure.
- Watch for small test charges. Fraudsters sometimes start with tiny purchases before going bigger, so scan your statements monthly.
- Stay skeptical of follow-up scams. After a breach, fake "support" emails and texts spike. Don't click urgent links or share info with anyone who reaches out first.
After a data breach, act quickly to protect your identity. Change passwords, turn on multi-factor authentication, review your accounts, freeze or monitor your credit, and keep a written record of every step in case fraud appears later.



